URLhaus Database

You are currently viewing the URLhaus database entry for http://8.218.138.77:8888/supershell/compile/download/%5Bwin which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3086390
URL: http://8.218.138.77:8888/supershell/compile/download/%5Bwin
URL Status:flame Online (spreading malware for 1 year, 8 month, 15 days, 10 hours, 49 minutes)
Host: 8.218.138.77
Date added:2024-08-03 08:26:22 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2024-08-03 08:27:13 UTC to abuse{at}alibaba-inc[dot]com)
Tags:supershell-c2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-08%5Bwinexe f65cf3103efa8daa19ebcee7c25d4a982f173f5fb5798d57040316dcc5e2aef2n/a 
2025-01-28n/aexe 9a33590dd66b3e3597bc4102c146c163600562195a97bf1d60de7a1a152d31c8n/a 
2025-01-26n/aexe 1e60937c72360fd80f1307f7549a7b45a5e7623ab153d6e0e40f7263b5fd310fn/a 
2025-01-25n/aexe ed56a3fbe031e2c1e4a0577359fc62f912de8b3584c3dace9b46071e2fa0b582n/a 
2025-01-15n/aexe 21418137ac29f0dd95698f7eeee2d6c773b8dae84bbae84dfde8bed41da8d82bn/a 
2025-01-13n/aexe ef292c266050cbb91b1e7ff9fbbf7074c1aa84ab95d4589071185523618dc7d1n/a 
2024-08-03n/aexe 9e3c0485f0c017c04f684859c8704a2ed0fc4f6515ec2299724bc2c32fa0c4d6Virustotal results 77.46%